7.5
CVSSv3

CVE-2020-13950

Published: 10/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 34

fedoraproject fedora 35

oracle instantis enterprisetrack 17.1

oracle instantis enterprisetrack 17.2

oracle instantis enterprisetrack 17.3

oracle enterprise manager ops center 12.4.0.0

oracle zfs storage appliance kit 8.8

Vendor Advisories

Synopsis Low: httpd:24 security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the httpd:24 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having ...
A flaw was found in Apache httpd The mod_proxy_wstunnel module tunnels non-upgraded connections (CVE-2019-17567) A flaw was found in HTTPd In some Apache HTTP Server versions, unprivileged local users can stop HTTPd on Windows The highest threat from this vulnerability is to system availability (CVE-2020-13938) A flaw was found In Apache httpd ...
A flaw was found in Apache httpd The mod_proxy_wstunnel module tunnels non-upgraded connections (CVE-2019-17567) A flaw was found in HTTPd In some Apache HTTP Server versions, unprivileged local users can stop HTTPd on Windows The highest threat from this vulnerability is to system availability (CVE-2020-13938) A flaw was found In Apache httpd ...
In Apache HTTP Server versions 2441 to 2446, mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2020-13950: Apache httpd: mod_proxy_http NULL pointer dereference <!--X-Subject-Header-End--> <!--X-Head-of-Message--> F ...